SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90769

HIGH · CVSS 7.7 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Open Notebook versions prior to 1.11.0 are vulnerable due to inadequate validation of the URL parameter in the POST /api/sources endpoint, enabling authenticated users to execute server-side requests to internal services. This flaw allows attackers to access sensitive information from cloud metadata and internal network services, posing a significant risk to data confidentiality and integrity. Organizations using Open Notebook should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90769
Severity
HIGH
CVSS
7.7
EPSS
N/A

Original NVD Description

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.